07-05-2015 10:12 PM - edited 03-12-2019 05:43 AM
ASA Firepower Sourcefire cannot add a manager (Firesight)
When adding the manager:
#configure manager add <firesight-ip> <key>
communication channel for management interface is not configured
07-06-2015 01:39 PM
Is your IP address and other network configuration bits setup and working in the FirePOWER module?
07-06-2015 05:56 PM
Hi Marvin,
Yes, ip address and default-gateway are setup already. I will ask my team to confirm this and send the screenshot for you.
Thanks!
07-07-2015 02:07 PM
During the sourcefire config process you're prompted to apply the IP and gateway to the management interface. Why they ask that boggles my mind, the module won't work unless you select yes and apply to the managment interface.
from the module paste the output of show network and show interfaces
07-07-2015 02:12 PM
They ask that because the FirePOWER module has its own independent routing table (albeit a very basic one) apart from the base ASA.
07-07-2015 02:20 PM
Yeah I knew about the bridged routing between module and ASA ( a basic verison of how the old 6500 switches with routing modules worked) my point was why ask to apply it as the module will not work without applying the routing to the management interface of the ASA should just auto apply that. I can see many engineers thinking at first glance no I want to reserve management interface for management (go figure right lol)
As for s.lachica a show network and show interfaces from the module CLI will answer just about all our questions.
07-07-2015 02:28 PM
Actually the base ASA management interface can be configured "no ip address" (and of course "no route management ___" while the FirePOWER module is configured with an address and gateway.
You can use the physical interface for ASA management also but only if it is in the same subnet as the FirePOWER module.
If you're only using the management interface for FirePOWER you can even use the ASA inside interface as the gateway - something you cannot do when you're also using the m0/0 interface for ASA management.
I think of them as two VMs on a hypervisor each with a virtual NIC that maps to the physical m0/0. Only difference is it's not quite as smart as you cannot tag the frames and direct them onto distinct subnets.
One thing coming in the next ASA release will be an actual separate routing table for the management interface on the ASA itself. (pause for applause ;) )
07-07-2015 02:36 PM
Yes, I have our management interface configured no ip address but it was of little concern as we don't use that interface for management of the boxes. The config script that runs on the module is rather vague and I'm guessing the OP or one of his team configured the IP address and gateway and did not apply it to the management interface. I heard you didnt have to use the management interface for communication to Firesight but I never really chased it down as it was a non issue for us.
09-01-2015 09:28 AM
Hi Guys I have the same problem , any solutions?
can ping manager server (192.168.0.15) is on different subnet no problem
My config on sfr module:
Configure Manager> add 192.168.0.15 key cisco
Communication channel for management interface is not configured!
Configure Manager> system
System> ping 192.168.0.15
PING 192.168.0.15 (192.168.0.15) 56(84) bytes of data.
64 bytes from 192.168.0.15: icmp_req=1 ttl=64 time=10.6 ms
64 bytes from 192.168.0.15: icmp_req=2 ttl=64 time=7.27 ms
64 bytes from 192.168.0.15: icmp_req=3 ttl=64 time=7.64 ms
--- 192.168.0.15 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2002ms
rtt min/avg/max/mdev = 7.271/8.537/10.698/1.537 ms
System> show network
----------------------------------------------------
IPv4
Configuration : manual
Address : 192.168.10.250
Netmask : 255.255.255.0
Gateway : 192.168.10.1
MAC Address : F4:CF:E2:C2:63:AC
Management port : 8305
----------------------------------------------------
Any ideas ?
I have configured this before never had this error.
Thanks
Martin
09-07-2015 06:28 PM
Hi bufycisco77,
Reimage the SFR on the cisco ASA. This resolved our issue last time. Search for the procedure of it in cisco.com, the key command is "recover".
Good luck!
Sonny
09-08-2015 01:36 AM
Hi Sonny,
yes, I did that. Also I have installed never image 5.4. before it was on 5.3.
And it is all good now.
Thanks
Martin
10-12-2015 03:41 AM
This happens due to some issue with sftunnel.conf file (mostly corrupted). You can follow instructions mentioned as per following document.
https://supportforums.cisco.com/discussion/12310476/fail-register-sfr-module
If this does not help, i would suggest to open a TAC case.
Thanks,
Dinkar
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide